The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Tue, 04 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling user's own address, allowing a low-privileged user to send one-time-passcode emails to arbitrary recipients and to exhaust the site's metered OTP allowance, preventing legitimate users from receiving their second-factor codes. | |
| Title | miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-04T17:37:08.049Z
Reserved: 2026-07-17T09:01:39.571Z
Link: CVE-2026-16035
Updated: 2026-08-04T17:37:04.468Z
No data.
No data.
OpenCVE Enrichment
No data.